Ok, I retract my previous statement. You ARE a god! Everything is back intact and MB updated! I have a couple last questions. I assume this is it for your help. Do you need anything more after I sent you that zip file? I also have been trying to use CyberDefender for anti-virus(this problem has hindered that effort). Is this something that would work well in conjunction with MB?
I need to go to work now, so I'll check back at the end of the day. Thanks again for all you did. I subscribed to MB on a recommendation from a geek friend and I will sing its praises to anyone who will listen.
- Malwarebytes Forum
- → Viewing Profile: Posts: PrimaryCriddle
Community Stats
- Group Members
- Active Posts 9
- Profile Views 852
- Member Title New Member
- Age Age Unknown
- Birthday Birthday Unknown
-
Gender
Not Telling
Posts I've Made
In Topic: Miekiemos is a god
19 May 2009 - 11:15 AM
In Topic: ClientMan & GameVance infections
18 May 2009 - 07:58 PM
OK, here goes.
I uninstalled StopZilla. I was only grasping at straws at possible solutions. I have you now!
All of the items including the two startup items are fixed.
Drivers32 key:
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
Class Name: <NO CLASS>
Last Write Time: 4/23/2009 - 7:58 PM
Value 0
Name: midimapper
Type: REG_SZ
Data: midimap.dll
Value 1
Name: msacm.imaadpcm
Type: REG_SZ
Data: imaadp32.acm
Value 2
Name: msacm.msadpcm
Type: REG_SZ
Data: msadp32.acm
Value 3
Name: msacm.msg711
Type: REG_SZ
Data: msg711.acm
Value 4
Name: msacm.msgsm610
Type: REG_SZ
Data: msgsm32.acm
Value 5
Name: msacm.trspch
Type: REG_SZ
Data: tssoft32.acm
Value 6
Name: vidc.cvid
Type: REG_SZ
Data: iccvid.dll
Value 7
Name: vidc.I420
Type: REG_SZ
Data: msh263.drv
Value 8
Name: vidc.iv31
Type: REG_SZ
Data: ir32_32.dll
Value 9
Name: vidc.iv32
Type: REG_SZ
Data: ir32_32.dll
Value 10
Name: vidc.iv41
Type: REG_SZ
Data: ir41_32.ax
Value 11
Name: vidc.iyuv
Type: REG_SZ
Data: iyuv_32.dll
Value 12
Name: vidc.mrle
Type: REG_SZ
Data: msrle32.dll
Value 13
Name: vidc.msvc
Type: REG_SZ
Data: msvidc32.dll
Value 14
Name: vidc.uyvy
Type: REG_SZ
Data: msyuv.dll
Value 15
Name: vidc.yuy2
Type: REG_SZ
Data: msyuv.dll
Value 16
Name: vidc.yvu9
Type: REG_SZ
Data: tsbyuv.dll
Value 17
Name: vidc.yvyu
Type: REG_SZ
Data: msyuv.dll
Value 18
Name: wavemapper
Type: REG_SZ
Data: msacm32.drv
Value 19
Name: msacm.msg723
Type: REG_SZ
Data: msg723.acm
Value 20
Name: vidc.M263
Type: REG_SZ
Data: msh263.drv
Value 21
Name: vidc.M261
Type: REG_SZ
Data: msh261.drv
Value 22
Name: msacm.msaudio1
Type: REG_SZ
Data: msaud32.acm
Value 23
Name: msacm.sl_anet
Type: REG_SZ
Data: sl_anet.acm
Value 24
Name: msacm.iac2
Type: REG_SZ
Data: C:\WINDOWS\system32\iac25_32.ax
Value 25
Name: vidc.iv50
Type: REG_SZ
Data: ir50_32.dll
Value 26
Name: msacm.l3acm
Type: REG_SZ
Data: C:\WINDOWS\system32\l3codeca.acm
Value 27
Name: wave
Type: REG_SZ
Data: serwvdrv.dll
Value 28
Name: wave1
Type: REG_SZ
Data: wdmaud.drv
Value 29
Name: midi
Type: REG_SZ
Data: wdmaud.drv
Value 30
Name: mixer
Type: REG_SZ
Data: wdmaud.drv
Value 31
Name: aux
Type: REG_SZ
Data: C:\WINDOWS\system32\..\mdkxo.brq
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server
Class Name: <NO CLASS>
Last Write Time: 8/16/2005 - 9:38 AM
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server\RDP
Class Name: <NO CLASS>
Last Write Time: 8/16/2005 - 9:38 AM
Value 0
Name: wave
Type: REG_SZ
Data: rdpsnd.dll
Value 1
Name: mixer
Type: REG_SZ
Data: rdpsnd.dll
Value 2
Name: MaxBandwidth
Type: REG_DWORD
Data: 0x56b9
Value 3
Name: wavemapper
Type: REG_SZ
Data: msacm32.drv
Value 4
Name: EnableMP3Codec
Type: REG_DWORD
Data: 0x1
Value 5
Name: midimapper
Type: REG_SZ
Data: midimap.dll
And lastly there was a new regedit created. I think that was it. Thank you soooooooo much for your help! I at least feel we are making progress.
-Craig
I uninstalled StopZilla. I was only grasping at straws at possible solutions. I have you now!
All of the items including the two startup items are fixed.
Drivers32 key:
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
Class Name: <NO CLASS>
Last Write Time: 4/23/2009 - 7:58 PM
Value 0
Name: midimapper
Type: REG_SZ
Data: midimap.dll
Value 1
Name: msacm.imaadpcm
Type: REG_SZ
Data: imaadp32.acm
Value 2
Name: msacm.msadpcm
Type: REG_SZ
Data: msadp32.acm
Value 3
Name: msacm.msg711
Type: REG_SZ
Data: msg711.acm
Value 4
Name: msacm.msgsm610
Type: REG_SZ
Data: msgsm32.acm
Value 5
Name: msacm.trspch
Type: REG_SZ
Data: tssoft32.acm
Value 6
Name: vidc.cvid
Type: REG_SZ
Data: iccvid.dll
Value 7
Name: vidc.I420
Type: REG_SZ
Data: msh263.drv
Value 8
Name: vidc.iv31
Type: REG_SZ
Data: ir32_32.dll
Value 9
Name: vidc.iv32
Type: REG_SZ
Data: ir32_32.dll
Value 10
Name: vidc.iv41
Type: REG_SZ
Data: ir41_32.ax
Value 11
Name: vidc.iyuv
Type: REG_SZ
Data: iyuv_32.dll
Value 12
Name: vidc.mrle
Type: REG_SZ
Data: msrle32.dll
Value 13
Name: vidc.msvc
Type: REG_SZ
Data: msvidc32.dll
Value 14
Name: vidc.uyvy
Type: REG_SZ
Data: msyuv.dll
Value 15
Name: vidc.yuy2
Type: REG_SZ
Data: msyuv.dll
Value 16
Name: vidc.yvu9
Type: REG_SZ
Data: tsbyuv.dll
Value 17
Name: vidc.yvyu
Type: REG_SZ
Data: msyuv.dll
Value 18
Name: wavemapper
Type: REG_SZ
Data: msacm32.drv
Value 19
Name: msacm.msg723
Type: REG_SZ
Data: msg723.acm
Value 20
Name: vidc.M263
Type: REG_SZ
Data: msh263.drv
Value 21
Name: vidc.M261
Type: REG_SZ
Data: msh261.drv
Value 22
Name: msacm.msaudio1
Type: REG_SZ
Data: msaud32.acm
Value 23
Name: msacm.sl_anet
Type: REG_SZ
Data: sl_anet.acm
Value 24
Name: msacm.iac2
Type: REG_SZ
Data: C:\WINDOWS\system32\iac25_32.ax
Value 25
Name: vidc.iv50
Type: REG_SZ
Data: ir50_32.dll
Value 26
Name: msacm.l3acm
Type: REG_SZ
Data: C:\WINDOWS\system32\l3codeca.acm
Value 27
Name: wave
Type: REG_SZ
Data: serwvdrv.dll
Value 28
Name: wave1
Type: REG_SZ
Data: wdmaud.drv
Value 29
Name: midi
Type: REG_SZ
Data: wdmaud.drv
Value 30
Name: mixer
Type: REG_SZ
Data: wdmaud.drv
Value 31
Name: aux
Type: REG_SZ
Data: C:\WINDOWS\system32\..\mdkxo.brq
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server
Class Name: <NO CLASS>
Last Write Time: 8/16/2005 - 9:38 AM
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server\RDP
Class Name: <NO CLASS>
Last Write Time: 8/16/2005 - 9:38 AM
Value 0
Name: wave
Type: REG_SZ
Data: rdpsnd.dll
Value 1
Name: mixer
Type: REG_SZ
Data: rdpsnd.dll
Value 2
Name: MaxBandwidth
Type: REG_DWORD
Data: 0x56b9
Value 3
Name: wavemapper
Type: REG_SZ
Data: msacm32.drv
Value 4
Name: EnableMP3Codec
Type: REG_DWORD
Data: 0x1
Value 5
Name: midimapper
Type: REG_SZ
Data: midimap.dll
And lastly there was a new regedit created. I think that was it. Thank you soooooooo much for your help! I at least feel we are making progress.
-Craig
In Topic: Trojan.bho strikes
18 May 2009 - 12:41 PM
Close this post. I've just read your instructions on how to use your help and will do it properly with a new topic. Thanks.
In Topic: Trojan.bho strikes
18 May 2009 - 12:21 PM
Sorry about the multiple posts. My bad-I've got to quit random clicking! I see the section on removing specific viruses and found the couple I have, but I can't update the virus definitions with these in place. Is there some way to manually add a file (copy onto a disc and physically moving it to the infected machine) to get the latest definitions?
In Topic: Trojan.bho strikes
18 May 2009 - 12:15 PM
PrimaryCriddle, on May 18 2009, 05:06 PM, said:
In reading these couple of posts, it looks like I CAN be helped! I have been infected by a couple of things that certainly seem to be gaining intelligence. I can no longer update Malwarebytes as it looks like I can not connect to you. I am on another computer just to communicate. It appears like a Windows update when shutting down that reinfects whatever it does. Malwarebytes was the only package that found all of the registry key infections, but now that I can't update the definitions, I'm really hosed. Is the ComboFix solution a possibility?
- Malwarebytes Forum
- → Viewing Profile: Posts: PrimaryCriddle
- Privacy Policy
- Terms of Use ·




Find content